Security

Your data security is our priority. Taskdop is built in accordance with international security standards.

Data Storage

All data is stored in ISO 27001 certified data centers in Turkey. For backup and disaster recovery, data is replicated across two geographically separate data centers within the same region. No third-country data transfers occur.

Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Transparent data encryption (TDE) is used at the database level. Backups are subject to the same encryption standards. Key management is handled through AWS KMS and is accessible only to authorized systems.

Access Control

Platform access is configured with role-based access control (RBAC). Each user can only access their authorized workspaces and tasks. All access logs are retained for 12 months and audited regularly. API keys are assigned individually and can be revoked when needed. SSO/SAML (Enterprise plan) is supported for centralized identity management.

KVKK / GDPR Compliance

Taskdop is fully compliant with the Turkish Personal Data Protection Law (KVKK No. 6698) and the EU General Data Protection Regulation (GDPR). Our customers act as data controllers while Taskdop acts as a data processor. A Data Processing Agreement (DPA) is provided to all Team and Enterprise customers. We are registered with the Data Controller Information System (VERBIS) under KVKK.

Uptime and SLA

Taskdop's target monthly uptime is 99.9%. An SLA (Service Level Agreement) is provided for Team and Enterprise customers. In case of SLA violation, service credits are applied at specified rates. Planned maintenance windows are announced at least 48 hours in advance via email and system notifications.

Data Deletion Policy

After account cancellation, all data is permanently deleted within 30 days. Deletion covers all backups as well. Customers can export their data (CSV/JSON) before cancellation if desired. Written confirmation is provided upon completion of deletion. Data subject to legal retention obligations is stored in a segregated environment for the legally mandated period.

Security Contact

For security vulnerability reports, please email [email protected]. Reports are responded to within 24 hours at the latest. Under our responsible disclosure policy, reported vulnerabilities are remediated within a reasonable timeframe after verification. As part of our SaaS architecture, regular penetration tests and security scans are conducted.